Versie 2026-08-14 · onderdeel van de overeenkomst tussen jou (“Klant”, verwerkingsverantwoordelijke) en Meritxell Media h.o.d.n. Mia Automation, KvK 80564186 (“Verwerker”)
Geldende versie, van kracht sinds 14 augustus 2026. Dit is de volledige en definitieve tekst; eerdere versies sturen we op verzoek toe. De bedrijfs- en registratiegegevens onderaan deze pagina zijn verifieerbaar bij de Kamer van Koophandel.
Deze verwerkersovereenkomst geldt automatisch voor elke zakelijke klant en hoeft niet apart ondertekend te worden. Wil je een ondertekend exemplaar voor je administratie? Print deze pagina (knop onderaan) of mail info@mia-automation.com.
1. Onderwerp en duur
De Verwerker verwerkt persoonsgegevens in opdracht van de Klant voor zover dat nodig is om de Mia-diensten te leveren (assistent, Mia OS, apps, gekoppelde diensten). Deze overeenkomst geldt zolang het abonnement loopt en eindigt na verwijdering van alle gegevens (art. 11).
2. Aard en doel van de verwerking
Het uitvoeren van opdrachten die de Klant of diens gebruikers aan Mia geven: e-mail- en agendabeheer, documentverwerking, het bouwen en draaien van apps, en de opslag daarvan in de eigen omgeving van de Klant.
3. Soorten gegevens en betrokkenen
Betrokkenen: de Klant zelf, medewerkers, klanten en relaties van de Klant, gebruikers van de apps van de Klant.
Gegevens: contactgegevens, communicatie-inhoud (e-mail, chat), agenda-items, documenten, klant- en ordergegevens in apps van de Klant. Geen bijzondere categorieën, tenzij de Klant die zelf laat verwerken; de Klant staat er dan voor in dat daarvoor een grondslag bestaat.
4. Instructies
De Verwerker verwerkt uitsluitend op gedocumenteerde instructie van de Klant (de opdrachten aan Mia en de instellingen van de omgeving), tenzij een wettelijke verplichting anders vereist — in dat geval informeren we de Klant vooraf, tenzij dat wettelijk verboden is. Meent de Verwerker dat een instructie in strijd is met de AVG of andere gegevensbeschermingsregels, dan meldt hij dat onmiddellijk aan de Klant en mag hij de uitvoering van die instructie opschorten tot de Klant deze bevestigt of aanpast.
5. Vertrouwelijkheid
Iedereen die onder gezag van de Verwerker toegang heeft tot persoonsgegevens is gebonden aan geheimhouding.
6. Beveiliging
De Verwerker treft passende technische en organisatorische maatregelen, waaronder: geïsoleerde omgeving per klant met firewall-scheiding, versleutelde off-site back-ups (encryptie vóór upload), dagelijkse geautomatiseerde security-audits, toegangsbeheer met wachtwoordkluis, en 24/7 monitoring met automatisch herstel. Zie ook https://mia-automation.com/security.
7. Subverwerkers
De Klant geeft algemene toestemming voor de volgende subverwerkers:
Subverwerker
Doel
Locatie
Anthropic
AI-modelverwerking van opdrachten
VS (EU-VS Data Privacy Framework)
Stripe
Betalingen en facturatie
EU/VS (DPF)
Google
Alleen door de Klant gekoppelde Workspace-diensten
EU/VS (DPF)
Nederlandse datacenters
Hosting van de eigen servers
Nederland
Nieuwe subverwerkers kondigen we minimaal 30 dagen vooraf aan; de Klant kan gemotiveerd bezwaar maken en bij een onopgelost bezwaar opzeggen. Aan elke subverwerker legt de Verwerker bij schriftelijke overeenkomst dezelfde verplichtingen op als in deze verwerkersovereenkomst staan. Komt een subverwerker zijn verplichtingen niet na, dan blijft de Verwerker daarvoor volledig aansprakelijk jegens de Klant.
8. Doorgifte buiten de EU
De omgeving van de Klant en de back-ups staan in Nederland. Doorgifte naar een land buiten de EER vindt alleen plaats voor de in artikel 7 genoemde subverwerkers en alleen met een geldig doorgiftemechanisme: het EU-VS Data Privacy Framework, aangevuld met de standaardcontractbepalingen van de Europese Commissie (Uitvoeringsbesluit (EU) 2021/914, module verwerker–verwerker) als achtervang. De Verwerker beoordeelt of aanvullende maatregelen nodig zijn en past die toe; verkeer is onderweg altijd versleuteld. Op verzoek verstrekt de Verwerker een overzicht van de doorgiften en de gehanteerde waarborgen.
9. Bijstand
De Verwerker helpt de Klant, voor zover redelijkerwijs mogelijk, bij verzoeken van betrokkenen (inzage, verwijdering, enz.) en bij verplichtingen rond beveiliging, datalekmeldingen en DPIA's. Bereikt een verzoek van een betrokkene de Verwerker rechtstreeks, dan handelt hij het niet zelf af maar stuurt hij het onverwijld door naar de Klant.
10. Datalekken
De Verwerker informeert de Klant zonder onredelijke vertraging, uiterlijk binnen 48 uur na ontdekking van een inbreuk in verband met persoonsgegevens, met de informatie die de Klant nodig heeft voor een eventuele melding aan de toezichthouder en betrokkenen.
11. Einde van de overeenkomst
Na beëindiging kan de Klant tot 30 dagen een volledige export van gegevens en apps opvragen. Daarna verwijdert de Verwerker alle persoonsgegevens definitief, inclusief back-ups binnen de daaropvolgende back-upcyclus, tenzij een wettelijke bewaarplicht geldt. Op verzoek bevestigt de Verwerker de verwijdering schriftelijk.
12. Audit
De Klant mag maximaal éénmaal per jaar (of na een datalek) een audit laten uitvoeren door een onafhankelijke, aan geheimhouding gebonden deskundige, na redelijke aankondiging en zonder toegang tot gegevens van andere klanten. De Verwerker stelt eerst bestaande rapportages (zoals de dagelijkse security-audits) beschikbaar en stelt alle informatie ter beschikking die nodig is om de naleving van artikel 28 AVG aan te tonen.
13. Aansprakelijkheid en rangorde
De aansprakelijkheidsregeling uit de algemene voorwaarden geldt ook voor deze verwerkersovereenkomst. Bij strijdigheid over gegevensbescherming gaat deze verwerkersovereenkomst voor.
Bedrijfsgegevens
Statutaire naam
Meritxell Media
Handelsnaam
Mia Automation
Adres
Van den Berghstraat 16, 5271 HS Sint-Michielsgestel, Nederland
Version 2026-08-14 · part of the agreement between you (“Customer”, controller) and Meritxell Media trading as Mia Automation, Chamber of Commerce 80564186 (“Processor”)
Current version, in force since 14 August 2026. This is the complete and definitive text; earlier versions are available on request. The company and registration details at the bottom of this page are verifiable at the Dutch Chamber of Commerce. In case of conflict between translations, the Dutch version prevails.
This DPA applies automatically to every business customer and does not need to be signed separately. Need a signed copy for your records? Print this page (button below) or email info@mia-automation.com.
1. Subject matter and duration
The Processor processes personal data on behalf of the Customer to the extent necessary to deliver the Mia services (assistant, Mia OS, apps, connected services). This DPA applies for the duration of the subscription and ends after deletion of all data (art. 11).
2. Nature and purpose
Carrying out the instructions the Customer or its users give Mia: email and calendar management, document processing, building and running apps, and storing these in the Customer's own environment.
3. Data categories and data subjects
Data subjects: the Customer, its employees, its customers and contacts, and users of the Customer's apps.
Data: contact details, communication content (email, chat), calendar items, documents, customer and order data in the Customer's apps. No special categories unless the Customer processes those itself; the Customer then warrants a legal basis exists.
4. Instructions
The Processor processes only on documented instructions from the Customer (the tasks given to Mia and the environment's settings), unless required by law — in which case we inform the Customer in advance, unless legally prohibited. If the Processor considers an instruction to infringe the GDPR or other data protection rules, it immediately notifies the Customer and may suspend execution of that instruction until the Customer confirms or amends it.
5. Confidentiality
Everyone with access to personal data under the Processor's authority is bound by confidentiality.
6. Security
The Processor implements appropriate technical and organisational measures, including: isolated per-customer environments with firewall separation, encrypted off-site backups (encrypted before upload), daily automated security audits, access management with a password vault, and 24/7 monitoring with automatic recovery. See also https://mia-automation.com/security.
7. Sub-processors
The Customer grants general authorisation for the following sub-processors:
Sub-processor
Purpose
Location
Anthropic
AI model processing of tasks
US (EU-US Data Privacy Framework)
Stripe
Payments and invoicing
EU/US (DPF)
Google
Only Workspace services connected by the Customer
EU/US (DPF)
Dutch data centres
Hosting of our own servers
Netherlands
New sub-processors are announced at least 30 days in advance; the Customer may object with reasons and, if unresolved, cancel. The Processor imposes on every sub-processor, by written agreement, the same obligations as set out in this DPA. If a sub-processor fails to fulfil its obligations, the Processor remains fully liable to the Customer for that failure.
8. Transfers outside the EU
The Customer's environment and the backups are located in the Netherlands. Transfers to a country outside the EEA only take place for the sub-processors listed in clause 7 and only under a valid transfer mechanism: the EU-US Data Privacy Framework, supplemented by the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914, processor-to-processor module) as a fallback. The Processor assesses whether supplementary measures are needed and applies them; traffic is always encrypted in transit. On request, the Processor provides an overview of the transfers and the safeguards applied.
9. Assistance
The Processor assists the Customer, where reasonably possible, with data subject requests (access, erasure, etc.) and with obligations regarding security, breach notifications and DPIAs. If a data subject request reaches the Processor directly, it does not handle it itself but forwards it to the Customer without delay.
10. Data breaches
The Processor informs the Customer without undue delay, at the latest within 48 hours of discovering a personal data breach, providing the information the Customer needs for any notification to the supervisory authority and data subjects.
11. End of the agreement
After termination the Customer may request a full export of data and apps for up to 30 days. The Processor then permanently deletes all personal data, including backups within the following backup cycle, unless a legal retention obligation applies. On request, the Processor confirms the deletion in writing.
12. Audit
The Customer may have an audit performed at most once a year (or after a breach) by an independent expert bound by confidentiality, after reasonable notice and without access to other customers' data. The Processor first provides existing reports (such as the daily security audits) and makes available all information needed to demonstrate compliance with Article 28 GDPR.
13. Liability and precedence
The liability arrangement in the terms of service also applies to this DPA. In case of conflict regarding data protection, this DPA prevails.
Company details
Registered name
Meritxell Media
Trading name
Mia Automation
Address
Van den Berghstraat 16, 5271 HS Sint-Michielsgestel, The Netherlands
Version 2026-08-14 · partie intégrante du contrat entre vous (« Client », responsable du traitement) et Meritxell Media exerçant sous le nom Mia Automation, KvK 80564186 (« Sous-traitant »)
Version en vigueur depuis le 14 août 2026. Il s'agit du texte complet et définitif ; les versions antérieures sont disponibles sur demande. Les informations d'entreprise et d'immatriculation en bas de page sont vérifiables auprès de la Chambre de commerce néerlandaise. En cas de divergence entre les traductions, la version néerlandaise fait foi.
Cet accord s'applique automatiquement à chaque client professionnel, sans signature séparée. Besoin d'un exemplaire signé ? Imprimez cette page (bouton ci-dessous) ou écrivez à info@mia-automation.com.
1. Objet et durée
Le Sous-traitant traite des données personnelles pour le compte du Client dans la mesure nécessaire à la fourniture des services Mia (assistante, Mia OS, applications, services connectés). L'accord vaut pendant la durée de l'abonnement et prend fin après la suppression de toutes les données (art. 11).
2. Nature et finalité
L'exécution des instructions données à Mia par le Client ou ses utilisateurs : gestion des e-mails et de l'agenda, traitement de documents, construction et exécution d'applications, et leur stockage dans l'environnement propre du Client.
3. Catégories de données et personnes concernées
Personnes concernées : le Client, ses collaborateurs, ses clients et contacts, et les utilisateurs de ses applications.
Données : coordonnées, contenus de communication (e-mail, chat), agenda, documents, données clients et commandes dans les applications du Client. Pas de catégories particulières, sauf si le Client les traite lui-même ; il garantit alors une base légale.
4. Instructions
Le Sous-traitant traite uniquement sur instruction documentée du Client, sauf obligation légale — auquel cas nous informons le Client au préalable, sauf interdiction légale. Si le Sous-traitant estime qu'une instruction constitue une violation du RGPD ou d'autres règles de protection des données, il en informe immédiatement le Client et peut suspendre l'exécution de cette instruction jusqu'à sa confirmation ou sa modification par le Client.
5. Confidentialité
Toute personne ayant accès aux données sous l'autorité du Sous-traitant est tenue à la confidentialité.
6. Sécurité
Le Sous-traitant met en œuvre des mesures techniques et organisationnelles appropriées : environnements isolés par client avec séparation pare-feu, sauvegardes chiffrées hors site (chiffrement avant transfert), audits de sécurité automatisés quotidiens, gestion des accès avec coffre-fort de mots de passe, et surveillance 24h/24 avec récupération automatique. Voir https://mia-automation.com/security.
7. Sous-traitants ultérieurs
Le Client autorise de manière générale les sous-traitants suivants :
Sous-traitant ultérieur
Finalité
Localisation
Anthropic
Traitement IA des tâches
États-Unis (Data Privacy Framework UE-US)
Stripe
Paiements et facturation
UE/US (DPF)
Google
Uniquement les services Workspace connectés par le Client
UE/US (DPF)
Centres de données néerlandais
Hébergement de nos propres serveurs
Pays-Bas
Tout nouveau sous-traitant est annoncé au moins 30 jours à l'avance ; le Client peut s'y opposer de manière motivée et, à défaut de solution, résilier. Le Sous-traitant impose à chaque sous-traitant ultérieur, par contrat écrit, les mêmes obligations que celles prévues par le présent accord. Si un sous-traitant ultérieur ne remplit pas ses obligations, le Sous-traitant en demeure pleinement responsable envers le Client.
8. Transferts hors UE
L'environnement du Client et les sauvegardes se trouvent aux Pays-Bas. Les transferts vers un pays hors EEE n'ont lieu que pour les sous-traitants ultérieurs listés à l'article 7 et uniquement sous un mécanisme de transfert valide : le Data Privacy Framework UE–États-Unis, complété par les clauses contractuelles types de la Commission européenne (décision d'exécution (UE) 2021/914, module sous-traitant à sous-traitant) à titre subsidiaire. Le Sous-traitant évalue la nécessité de mesures supplémentaires et les applique ; le trafic est toujours chiffré en transit. Sur demande, il fournit un aperçu des transferts et des garanties appliquées.
9. Assistance
Le Sous-traitant assiste le Client, dans la mesure du raisonnable, pour les demandes des personnes concernées et pour les obligations de sécurité, de notification de violations et d'AIPD. Si une demande d'une personne concernée lui parvient directement, il ne la traite pas lui-même mais la transmet sans délai au Client.
10. Violations de données
Le Sous-traitant informe le Client sans retard injustifié, au plus tard 48 heures après la découverte d'une violation de données personnelles, avec les informations nécessaires à une éventuelle notification.
11. Fin du contrat
Après la fin du contrat, le Client peut demander une exportation complète pendant 30 jours. Le Sous-traitant supprime ensuite définitivement toutes les données personnelles, y compris les sauvegardes lors du cycle suivant, sauf obligation légale de conservation. Sur demande, il confirme la suppression par écrit.
12. Audit
Le Client peut faire réaliser un audit au maximum une fois par an (ou après une violation) par un expert indépendant tenu à la confidentialité, après préavis raisonnable et sans accès aux données d'autres clients. Le Sous-traitant met d'abord à disposition les rapports existants (comme les audits de sécurité quotidiens) ainsi que toute information nécessaire pour démontrer le respect de l'article 28 du RGPD.
13. Responsabilité et primauté
Le régime de responsabilité des conditions générales s'applique également à cet accord. En cas de conflit concernant la protection des données, le présent accord prévaut.
Informations sur l'entreprise
Dénomination légale
Meritxell Media
Nom commercial
Mia Automation
Adresse
Van den Berghstraat 16, 5271 HS Sint-Michielsgestel, Pays-Bas